INTA Data Committee

Jurisdictions / Australia

Australia

Asia-Pacific · Law stated as at Aug 2026

Overview — from the Part II reportFixed reference content

Australia does not formally recognize data as a distinct intellectual property asset; protection instead comes from an overlapping combination of copyright, equitable confidentiality, contract law, and privacy regulation. Copyright under the Copyright Act 1968 (Cth) has become of limited practical value for corporate data assets: after IceTV v. Nine Network and Telstra v. Phone Directories, protection requires original expression by a discernible human author applying creative judgment, which excludes the automated, machine-collected datasets that dominate modern data practice.

With no standalone trade secrets statute, confidential information is protected through the equitable duty of confidence, whose criteria were set out in Smith Kline & French v. Department of Community Services: the information must have the necessary quality of confidence, be disclosed in circumstances importing an obligation of confidence, and be subject to actual or threatened misuse; detriment is not strictly required. Contract law is therefore the most effective tool for controlling data use — through licensing agreements, NDAs, terms of use, and API agreements — though privity limits protection against third-party scrapers.

The Privacy Act 1988 (Cth) anchors personal data regulation through the thirteen Australian Privacy Principles, and recent reforms sharply increased penalties — up to AU$50 million, three times the benefit obtained, or 30 percent of adjusted turnover for serious breaches. In Clearview AI and Australian Information Commissioner, the Administrative Appeals Tribunal held scraping biometric data for facial recognition software to violate privacy law. AI-specific regulation is still emerging, with a proposed National Framework for Safe and Responsible AI contemplating risk-tiered safeguards for high-impact systems.

Key takeaways

  • Australian copyright rarely protects modern datasets because machine-collected data lacks the human authorship courts now require.
  • Equitable breach of confidence is the primary quasi-trade-secret remedy, so documenting confidentiality measures and disclosure circumstances is essential.
  • Contracts — licenses, NDAs, terms of use, and API agreements — are the most effective mechanism for controlling data access and AI training uses.
  • Privacy Act penalties now reach AU$50 million or more for serious breaches, and the Clearview AI decision shows regulators will act against data scraping.
  • There is no sui generis database right and no enacted AI law; a National Framework for Safe and Responsible AI remains at the proposal stage.

Primary legal instruments

Copyright Act 1968 (Cth)IceTV v. Nine Network (2009)Telstra v. Phone Directories (2010)Smith Kline & French v. Dept. of Community Services (1990)Privacy Act 1988 (Cth)Clearview AI and Australian Information Commissioner (2023)

AI-assisted summary of the report, editorially reviewed before publication · AI transparency

Protection mechanisms

Report-derived analysis per mechanism. The report text is fixed; committee members with contributor access can revise the rating (with an audit trail) and add notes below each block.

Recent Developments

Live updates contributed by committee members and the AI research bot — separate from the fixed report content above.

Analysis of AI and copyright implications for Australian data centers

25 Aug 2026Guidance#Copyright#AI-Specific RulesAI-generated

This article examines how Australia's approach to AI and copyright law will shape the future demand for data center capacity within the country. It highlights the direct link between legal frameworks governing AI training data and the infrastructure required to support AI development. The analysis suggests that policy decisions in this area will have significant economic and technological consequences.

Pinsent Masons

Government rejects proposed copyright exemption for AI training data

24 Aug 2026Rule changeApprovedAustralian Government#Copyright#AI-Specific RulesAI-generated

The Australian government recently declined a proposal from the tech industry to introduce a copyright exemption for training artificial intelligence models. This decision indicates a cautious stance on allowing AI systems to use copyrighted material without explicit licensing. The rejection underscores the ongoing debate about balancing innovation with the protection of intellectual property rights in the age of AI.

YouTube · Semafor

Analysis of data centers, AI training, and Australian copyright law implications

19 Aug 2026Guidance#Copyright#AI-Specific RulesAI-generated

This article examines the complex relationship between data centers, artificial intelligence training, and Australia's copyright framework. It highlights the unresolved challenges concerning how existing copyright and intellectual property laws apply to the vast amounts of data processed for AI development. The analysis underscores the need for clarity in this evolving legal landscape for all involved parties.

Thomson Reuters

OAIC updates APP 3 guidance to cover data scraping, AI and automated collection of personal information

13 May 2026AI-generated

On 13 May 2026 the OAIC published updated guidance on Australian Privacy Principle 3 (collection of solicited personal information), adding contemporary examples covering AI, facial recognition, data scraping, web crawling, tracking pixels and data broking. The guidance makes clear that personal information being publicly available online does not permit unrestricted collection: scraped data must still satisfy APP 3 or APP 4 and remains subject to all APPs once collected, with particular caution required where scraping may sweep in sensitive information. This tightens the compliance frame for building datasets, including AI training corpora, from public sources.

OAIC releases exposure draft of the Children's Online Privacy Code for consultation

31 Mar 2026AI-generated

On 31 March 2026 the OAIC published the exposure draft of the Children's Online Privacy Code, a binding code mandated by the first tranche of Privacy Act reforms, opening a 60-day consultation that closed on 5 June 2026. The draft requires organisations to consider children's best interests before collecting, using or disclosing their personal information, restricts use of children's data for targeted advertising, and provides deletion rights, applying broadly to apps, games, streaming and educational services. The OAIC intends to register the Code by 10 December 2026.

Productivity Commission's final 'Harnessing Data and Digital Technology' report tabled in Parliament

29 Jan 2026AI-generated

The Productivity Commission's final report on harnessing data and digital technology, publicly released on 19 December 2025, was tabled in Parliament on 29 January 2026. It recommends against immediately introducing a text-and-data-mining copyright exception for AI training, favouring a wait-and-see approach, and proposes outcomes-based privacy regulation built around a 'fair and reasonable' test plus a rightsized Consumer Data Right. The report frames the government's forthcoming decisions on AI, copyright and data-access reform.

Productivity Commission